使用Ktor embeddedServer时,如何安全存储Google OAuth等密钥?
使用embeddedServer时存储敏感凭证的方案
问题根源
embeddedServer不会像EngineMain那样自动加载application.conf并将配置注入到environment.config中,所以直接调用environment.config.propertyOrNull会返回null,需要手动处理配置加载。
方案一:手动加载resources中的配置文件
- 在
src/main/resources下创建application.conf,按自定义结构存放敏感信息:
google { oauth { client_id = "你的Google OAuth Client ID" } mail { app_password = "你的Google应用密码" } }
- 在代码中手动加载配置并读取:
import com.typesafe.config.ConfigFactory import io.ktor.server.config.HoconApplicationConfig import io.ktor.server.netty.Netty import io.ktor.server.engine.embeddedServer fun main() { // 加载resources目录下的application.conf val config = HoconApplicationConfig(ConfigFactory.parseResources("application.conf")) // 读取配置项 val googleClientId = config.propertyOrNull("google.oauth.client_id")?.getString() ?: "" val googleAppPassword = config.propertyOrNull("google.mail.app_password")?.getString() ?: "" embeddedServer(Netty, port = 8080) { // 在这里使用获取到的凭证 }.start(wait = true) }
方案二:使用环境变量(更安全)
将敏感信息存入系统环境变量,避免写入配置文件或代码:
设置环境变量:
- Windows:
set GOOGLE_CLIENT_ID=你的Client ID、set GOOGLE_APP_PASSWORD=你的应用密码 - Linux/macOS:
export GOOGLE_CLIENT_ID=你的Client ID、export GOOGLE_APP_PASSWORD=你的应用密码
- Windows:
在代码中读取环境变量:
import io.ktor.server.netty.Netty import io.ktor.server.engine.embeddedServer fun main() { val googleClientId = System.getenv("GOOGLE_CLIENT_ID") ?: "" val googleAppPassword = System.getenv("GOOGLE_APP_PASSWORD") ?: "" embeddedServer(Netty, port = 8080) { // 使用环境变量中的凭证 }.start(wait = true) }
方案三:外部配置文件
如果不想把配置放在resources里,可以指定外部配置文件路径加载:
import com.typesafe.config.ConfigFactory import io.ktor.server.config.HoconApplicationConfig import java.io.File val config = HoconApplicationConfig(ConfigFactory.parseFile(File("/path/to/your/config.conf")))
内容的提问来源于stack exchange,提问作者user22647102
相关产品推荐
相关产品推荐

